Privacy Policy
Effective: September 2026 (version 2026-09-v4)
1. Scope
This Privacy Policy explains how Trinovar Tech LLC, operating as VozyScribe, collects and uses information when you use our transcription platform. A limited AI-assisted Summary feature is available on every plan, under its own monthly quota; the Timeline, Important items & follow-ups, and Objections & rulings features are additional capabilities available only on the Legal plan. VozyScribe does not control or review what any user chooses to record or upload — see our Terms of Service for your obligations regarding lawful content and consent.
2. Information We Collect
We collect account information such as your name, email address, authentication credentials — including securely hashed passwords where password-based authentication is used — or Google OAuth identity data, email-confirmation status, and account settings. We collect billing identifiers and subscription status supplied through Stripe. Full payment card and bank account details are collected and processed directly by Stripe and are not received or stored by VozyScribe. We also collect usage and operational metadata, including activity, feature usage, error and security logs, IP-related request data, browser or device information, and timestamps.
To keep accounts secure we also collect the information behind two-step verification and your signed-in sessions: an encrypted authenticator secret and hashed recovery codes if you turn on two-step verification, and, for each active session or trusted device, the browser or device type, IP address, and sign-in and last-activity times, which you can see and end in Settings. We keep a security log of sign-ins, failed sign-in attempts, account and plan changes, exports, and actions taken by our staff on customer accounts for 400 days, so that we can investigate problems and show that our controls work. When you buy an add-on, we record the purchase and your remaining add-on minutes and credits.
Customer Content includes uploaded audio, documents you upload to a case folder (PDF and images) and the short notes you attach to them, the vocabulary terms you save, generated transcript text, timestamps, word-level and speaker data, participant labels, and legal-analysis outputs — Summary, Timeline, Important items & follow-ups, and Objections & rulings — including their source quotes and timestamps.
If you are given early access to a beta version, we also keep a record of your invitation (who invited you and when, and for how long), the date and version of the beta access agreement you accepted, and a hashed temporary password until you replace it. We never store the temporary password itself.
3. How We Process and Share Information
We process information to authenticate users, store and transcribe audio, generate requested analyses, provide exports, maintain security, administer subscriptions, respond to support requests, and comply with law. We share information only as needed with service providers that perform these functions for us:
- Cloudflare R2 stores uploaded audio and the documents you upload to case folders. The application uses signed URLs for controlled object access. Documents are stored for you; they are not sent to any AI provider.
- AssemblyAI receives temporary signed HTTPS access to audio, and the vocabulary terms you have saved so it can recognize them, solely to perform requested transcription.
- ElevenLabs, for recordings we send to it as our transcription provider instead of AssemblyAI, receives the same temporary signed HTTPS access to audio solely to perform requested transcription. What it retains is subject to its own terms and account settings.
- Anthropic Claude receives transcript text, speaker labels, and instructions solely to generate the analyses you request and, when a transcript finishes, to suggest a title for it and to detect whether it has legal content. It does not receive raw audio.
- Stripe processes subscription and billing transactions and provides related billing identifiers and status.
- Google handles optional OAuth sign-in. Google Gemini is not used by VozyScribe.
- Our email provider (an SMTP service or Resend) sends account, confirmation, security, and service emails.
Transfers to these processors are made through encrypted HTTPS/TLS connections where the integration supports them and only to provide the requested service.
Who on our team can see what. A few authorized people on our team can see basic account information, so they can help you when something goes wrong: your email address, your plan and subscription status, how many minutes and credits you have used, when and from where you signed in (IP address and browser type), and whether each of your recordings finished processing, with a short technical message if it did not. We use this only to answer your support requests, keep the service secure, handle billing, and fix problems.
We do not read your content. Our team does not open your audio, transcripts, or analyses, and does not see the titles of your recordings, unless you ask us to look at something to help you or the law requires it. Whenever someone on our team looks at a customer's records, we keep a log of it.
4. No AI Training Commitment
VozyScribe does not use Customer Content to train public or commercial AI models. Provider-side handling and any provider training commitments remain subject to the applicable subprocessor contracts, policies, and configured account settings. We do not make a broader provider guarantee unless it has been separately verified in those agreements and settings.
5. Retention and Deletion
Uploads rejected during validation are deleted. Temporary local conversion files are removed after submission for transcription.
Original audio for a completed transcript is automatically deleted from Cloudflare R2, and VozyScribe requests deletion of the related AssemblyAI transcription artifact, after a retention period measured from when transcription completes. That period is fixed at completion based on the active plan: Free Trial — 7 days; Pro — 30 days; Premium — 90 days; Legal — 90 days. A later upgrade, downgrade, or cancellation does not change an existing transcript’s scheduled audio-deletion date. This automatic deletion affects the original audio file only, and it is permanent: once the audio is deleted, it cannot be recovered or replayed, even though the transcript itself remains available.
The transcript text, speaker labels, timestamps, and any legal-analysis outputs remain in your account until you delete the transcript or your account. They are not automatically deleted on a plan-based schedule.
Documents you upload to a case folder are not affected by the audio retention period. They stay until you delete them, or until you delete your account, when they are deleted with your other content. Deleting a document also deletes its stored file.
You may delete a transcript (audio and all associated data) manually at any time. Deleting a transcript removes its database record and the related Cloudflare R2 object, and VozyScribe requests deletion of the related AssemblyAI transcription artifact when one exists.
You may request deletion of your account through Settings. We send a confirmation link by email before deletion proceeds. After you confirm that request, VozyScribe cancels any active subscription and deletes your transcripts and their associated audio, speakers, timestamps, and legal-analysis outputs immediately, requesting deletion of related AssemblyAI transcription artifacts when they exist. Where an in-progress transcription cannot be immediately canceled through the provider integration, that job is given up to 24 hours to finish before being deleted regardless of status — all other Customer Content associated with your account is deleted right away. We anonymize the account record and may retain the minimum information needed for billing, security, fraud prevention, legal compliance, or to resolve a dispute. Provider retention remains subject to each provider’s terms, account configuration, and legal obligations.
6. Your Rights and Choices
You control most of your data yourself, at any time and without asking us:
- See and export your transcripts as Word, PDF, text, or subtitle files, or export a whole folder from your transcripts list.
- Correct them in the editor: the text, the speaker names, and the title.
- Change your name and your email address in Settings. A new email address takes effect once you open the link we send to it, and we tell the old address.
- Download a copy of your data in Settings: your account details, plan and purchases, usage, where you have signed in, and the security log about your account. Your transcripts are exported from the editor or your transcripts list.
- Delete a transcript, with its audio, from your transcripts list.
- Delete your account in Settings, under Danger zone. We email you a confirmation link, and once you click it your transcripts, audio, and analyses are deleted (see Retention and Deletion above).
- Manage how you sign in in Settings: see where you are signed in and end any session, turn two-step verification on or off, and choose which emails you get.
You can write to us at info@vozyscribe.com for the things the app does not let you do on your own: to ask us about how your data is handled, to ask us to fix or delete something that you cannot change yourself, or to make a complaint. We may need to confirm it is really you, and we may keep some information when the law requires it or when we need it for security, fraud prevention, billing, or to resolve a dispute. These rights apply subject to the law that applies to you.
7. Cookies
VozyScribe uses only strictly necessary cookies required to keep you signed in. VozyScribe does not use analytics, advertising, or tracking cookies.
- vozyscribe.auth.v2 — keeps you signed in. HTTP-only, sent only over HTTPS in production, expires after 8 hours.
- vozyscribe.mfa — a short-lived cookie set between entering your password and entering your two-step verification code, so the second step can be completed. HTTP-only, sent only over HTTPS in production.
- vozyscribe.trusted — set only if you choose “trust this device” after a two-step verification code. It holds a random token (we store only a hash of it) so that this browser is not asked for the code again for 30 days. HTTP-only, sent only over HTTPS in production. You can remove it by ending the device in Settings.
- Antiforgery cookie — a security token that protects forms (such as sign-in and billing) from being submitted by another site.
- Language preference — stored only if you choose a language (English or Spanish), so the site remembers it. It holds no personal information and expires after one year.
- Stripe — on the plans and billing pages, where you pay, Stripe’s payment form may set its own cookies and similar storage for security and fraud prevention. We do not control them; see Stripe’s privacy policy.
- vozyscribe.google.external — a short-lived cookie used only during Google sign-in to correlate the OAuth redirect back to your browser. HTTP-only, sent only over HTTPS in production, expires after 10 minutes.
8. Security
We use reasonable technical and organizational safeguards designed to protect information. These include encryption in transit and audio storage that is not publicly accessible, optional two-step verification with an authenticator app (required for staff who use our administration tools), temporary lockout after repeated failed sign-ins, the ability to see and end your active sessions, and the security log described above. No system or transmission is completely secure, so you should protect account credentials and promptly report suspected unauthorized access.
9. Policy Updates
We may update this Privacy Policy by posting a revised version with a new effective date. Questions about this Policy may be sent to info@vozyscribe.com.